2023 Wippy (nRiZE) — identity-verification flaw; 736 dating-app profiles (PIPC fine Aug 2026)
Data compromised
Nicknames, profile photos, dates of birth, education, occupation, height, blood type, and other profile fields for 736 accounts
Technical writeup
Verified regulator enforcement — disclosed August 31, 2026. South Korea’s PIPC fined nRiZE, operator of the Wippy dating app, ₩118.44 million plus a ₩3.6 million administrative penalty after a March 2023 incident in which an attacker abused an identity-verification weakness to exfiltrate profile data from 736 accounts (nicknames, photos, dates of birth, education, occupation, height, blood type, and related fields). The fine was announced alongside the GS Retail and SK Telecom ifland actions in the same PIPC plenary batch. recordsAffected 736 from regulator attestation; companyConfirmed true.
Root cause
Hacker exploited vulnerability in Wippy identity-verification system (March 2023) per PIPC August 2026 enforcement action